HSP GRUPPE chooses ChatGPT Enterprise for tax consulting: governance enters the most regulated domain
OpenAI publishes the case study of HSP GRUPPE, a German tax consulting group that has integrated ChatGPT Enterprise into its daily operations. The document declares governance and compliance: access controls, data rules, usage limits. It’s the second case published in a week on a regulated company adopting AI with explicit rules, after Univé in the insurance sector.
For those bringing AI into a regulated company, the pattern is consolidating. Governance before the use case, granular permissions, starting with a restricted group before expanding. HSP GRUPPE operates in taxation, where every output touches legal obligations and sensitive tax data: an error on a regulation means professional liability. If AI enters this domain with declared controls, the model is replicable across other regulated sectors, from finance to healthcare.
The case study is public on OpenAI’s website. Reading it before starting an enterprise evaluation in a regulated domain takes just a few minutes and helps avoid starting from zero on governance decisions.
In detail
Univé and HSP GRUPPE are two case studies published by OpenAI five days apart, in two different regulated sectors: insurance and tax consulting. These aren’t generic testimonials. Both describe operational controls, data governance, and an adoption path that starts with a restricted group before expanding. The temporal coincidence suggests an OpenAI investment in showing how its enterprise platform can hold up in contexts where errors carry legal costs. The narrative is similar in both cases: controlled start, permission definition, gradual expansion.
Context matters. On the same day as the Univé case study, OpenAI also published its position on AI governance for Europe, aligning with the EU AI Act. August’s enterprise case studies are the practical demonstration of that policy: how a compliance principle translates into concrete controls over who sees what, which data enters the model and which stays out, who approves outputs before they reach the customer. Regulated companies need to demonstrate that sensitive data doesn’t end up in training or accessible to unauthorized parties. ChatGPT Enterprise responds with specific administrative controls.
For German tax consulting, this point is particularly sensitive. Tax data is personal, deadlines are imperative, and regulations change. The case study describes ChatGPT Enterprise as a tool that creates additional capacity for consultants, freeing time for client relationships. The professional remains responsible for the opinion. It’s the same angle as Univé: AI enhances, it doesn’t replace. The difference from other sectors is that here the professional answers with their own name before the tax authority and the client. AI serves to reduce repetitive work, like regulatory research, leaving the final decision to the person.
The limits of what we know. The document is published by OpenAI on its own site. It’s a vendor case study: it selects the customer, chooses which numbers to show, constructs the narrative. It’s not an independent audit and doesn’t claim to be. What makes it useful is the operational description of controls, not the measurement of productivity results, which is the number the vendor chooses to publish. Details on internal integrations or specific approval workflows are synthetic.
For those evaluating a similar adoption, the useful question concerns which of these controls can be replicated in your own domain. You need to look at permissions, data filters, and approval phases that you can put in place today with available tools, setting aside marketing claims about productivity. The answer depends on context, but the two case studies offer a concrete starting checklist.